# Microsoft Rayfin: a TypeScript-decorator BaaS that deploys onto Microsoft Fabric

> Rayfin scaffolds a backend from TypeScript entity decorators and runs it on Microsoft Fabric. The install path is short and the local mode is still experimental, so the decision hinges on whether Fabric is already in your stack.

**microsoft/rayfin** — Backend-as-a-Service with built-in auth, data, and more

- Repository: https://github.com/microsoft/rayfin
- Stars: 620 · Forks: 63
- Language: Unknown
- License: MIT
- Published: 2026-09-20 · Updated: 2026-09-20 · Language: en
- Canonical page: https://hysenlabs.com/projects/microsoft-rayfin

## The problem Rayfin removes: backend plumbing before the first feature

Most small applications need the same five things before they do anything interesting: a database, a way to authenticate users, HTTP endpoints over that data, somewhere to put files, and somewhere to host the front end. Rayfin's pitch is that you describe the first of those in TypeScript and the platform derives the rest. The README describes it as a "fully managed Backend-as-a-Service (BaaS) platform" and lists exactly those five managed pieces: database, authentication, data APIs, storage and hosting.

The audience is narrow but real. It is a team that already has a data model in mind and does not want to spend a sprint wiring an ORM, an auth provider and a deployment pipeline. It is also, given the plugin section of the README, a team that works inside an AI coding agent and wants the agent to know how Rayfin projects are structured. A solo developer with no Fabric tenant gets much less out of it, because the managed half of the promise lives in Fabric.

## How the decorator-to-deployment mechanism works

The mechanism is a schema-first loop. You write entity classes annotated with TypeScript decorators, and those decorators come from @microsoft/rayfin-core, described in the README's package table as "Entity decorators, schema definitions, and core types". The decorator metadata is the source of truth for the data model; Rayfin provisions the backend from it rather than asking you to write migration files or table definitions by hand.

On the client side the packages are split by concern rather than bundled into one SDK. @microsoft/rayfin-client is the main client SDK, @microsoft/rayfin-data is a "Type-safe client library for Data API Builder endpoints", @microsoft/rayfin-auth holds authentication utilities, @microsoft/rayfin-storage covers storage operations, and @microsoft/rayfin-functions is the functions runtime. The presence of a Data API Builder client tells you something concrete about the data plane: the generated endpoints follow that shape rather than a bespoke REST convention.

Authentication has its own provider package. @microsoft/rayfin-auth-provider-fabric is described as a "Fabric brokered authentication provider", which means sign-in is brokered through Fabric rather than being a standalone identity service you configure separately. That is the single most consequential architectural fact about Rayfin: the governance and identity story is Fabric's, not Rayfin's own.

## Installing Rayfin and running a first deploy

The README gives one scaffolding command and one deploy command. The scaffolder is @microsoft/create-rayfin, and the README states it produces a project with data models, authentication, APIs and a ready-to-deploy app.

```bash
npm create @microsoft/rayfin@latest
```

After the scaffolder finishes you have a project directory with the entity definitions and the wiring already in place. To deploy and run it, the README shows a single CLI invocation through npx:

```bash
npx rayfin up
```

The CLI behind that command is @microsoft/rayfin-cli, described as the tool for "scaffolding, deploying, and managing Rayfin apps". What you should expect to see is a deployment against your Fabric environment; the README does not spell out the prompts, the target selection or the output format, so treat the first run as a discovery step and read the console output rather than assuming a fixed sequence.

If you work inside an agent, the README offers a second install path. For Claude Code the commands are slash commands, and other agents use their own marketplace verbs:

```bash
copilot plugin marketplace add microsoft/rayfin
copilot plugin install rayfin@rayfin-skills
```

The README states the plugin supports Claude Code, Cursor, Codex, GitHub Copilot CLI, Grok Build, Kimi Code, Visual Studio Code agent plugins and Gemini CLI, and that Grok Build reads Claude Code marketplaces automatically. A cross-agent alternative is also given: `npx plugins add microsoft/rayfin`.

## Local development is experimental, and that is the main limitation

The README is unusually direct here: "Rayfin supports a pure local development experience (no cloud resources required). This is currently experimental and great for trying out Rayfin or building offline." The word experimental is the project's own. There is no separate stability statement, no list of what works offline and what does not, and no documented fallback for the parts of the platform that only exist in Fabric.

That matters because of what Rayfin is built on. The README states plainly that Rayfin is built on Microsoft Fabric, and that Fabric provides "centralized data discovery, access control, and governance capabilities". A managed BaaS whose identity provider is a Fabric brokered provider cannot be fully reproduced on a laptop. So the local template linked from the README, the Todo Local Experimental template in the awesome-rayfin repository, is best read as a way to try the shape of a Rayfin project, not as a promise that your production configuration behaves the same way locally.

A second limitation is portability. Every managed capability in the list, from the database to hosting, is delivered through Fabric. If your organisation runs on AWS, or if you need the backend to be deployable to more than one cloud, Rayfin is the wrong tool and no amount of decorator ergonomics changes that. The README does not document an alternative deployment target.

## Rayfin compared with a self-assembled stack

The honest alternative is not another BaaS product; it is assembling the same five pieces yourself. A typical stack would be Postgres or SQLite for the database, an ORM with a migration tool for the schema, a hosted identity provider for auth, a small HTTP framework for the data endpoints, and an object store for files. The difference in approach is where the schema lives. In Rayfin the data model is the TypeScript source, and the platform reads it. In a self-assembled stack the schema lives in migration files and the ORM types are generated from the database, so the database is the source of truth and the types follow.

That inversion has a practical consequence. Rayfin projects are easy to start and hard to move, because the deployment surface is Fabric. A self-assembled stack is slower to start and portable, because each piece is replaceable. Neither is universally better. If you have ever spent a week on auth and migrations before writing a feature, Rayfin's trade is attractive. If you have ever had to migrate a backend off a managed platform under deadline, it is not.

The README also positions Fabric governance as a benefit rather than a constraint: apps "inherit enterprise-grade security and governance out of the box". For a team inside an organisation that already uses Fabric, that is a genuine reduction in work. It is not a claim about Rayfin's own security model, and the README does not document one separately.

## Maintenance, licence, and what upgrading costs

The repository is not archived, and its last push was on 2026-09-17. The recent release history is entirely template releases: templates-v1.1.2 on 2026-08-28, templates-v1.1.3 on 2026-08-31, and templates-v1.1.4 on 2026-09-17. That cadence says the template surface is moving faster than anything else visible in the release list, which is consistent with a project still settling its scaffolding conventions.

The upgrade cost is therefore concentrated in the scaffolder and the CLI rather than in the runtime libraries. Because the project is distributed as a set of npm packages, @microsoft/rayfin-cli, @microsoft/rayfin-core, @microsoft/rayfin-client and the rest version independently, a project can end up with a CLI newer than the core decorators it was generated against. The README does not document a version compatibility matrix or a rollback procedure, so pinning the versions your scaffolder produced is the only reliable reference you have.

Rayfin is MIT licensed. That is a permissive licence and it does not restrict commercial use, but the licence covers the code in this repository. It says nothing about the terms of the Microsoft Fabric service that the deployed application depends on, and the README does not discuss service pricing or quotas. Treat those as two separate questions.

## Conclusion

Adopt Rayfin if your organisation already runs Microsoft Fabric and you want the database, auth, data APIs, storage and hosting provisioned from TypeScript decorators rather than assembled by hand. Skip it if you need a cloud-neutral backend, if you want a local-only development loop today, or if you cannot accept that the platform underneath is Fabric. Before committing, verify three things: that your Fabric tenant and governance setup is ready, that the experimental local template covers the workflows you need, and that the CLI commands in the current README still match the version the scaffolder installs. The repository's last push was on 2026-09-17 and its most recent release is templates-v1.1.4, so check the npm versions of @microsoft/rayfin-cli and @microsoft/rayfin-core rather than trusting a blog post.

## FAQ

### How do I install Rayfin?

The README's install path is the scaffolder: run npm create @microsoft/rayfin@latest, which produces a project containing data models, authentication, APIs and a ready-to-deploy app. Deployment is then npx rayfin up.

### What is Rayfin?

Rayfin is a fully managed Backend-as-a-Service platform from Microsoft. You define a data model with TypeScript decorators and the platform provisions and manages the database, authentication, data APIs, storage and hosting.

### What is Rayfin Fabric?

It refers to Rayfin running on Microsoft Fabric. The README states Rayfin is built on Fabric, which supplies centralized data discovery, access control and governance, and the auth package is a Fabric brokered authentication provider.

### What is the Rayfin CLI?

The CLI is the @microsoft/rayfin-cli package, described in the README as the tool for scaffolding, deploying and managing Rayfin apps. The README's deploy example is npx rayfin up.

### What is the Rayfin SDK?

The SDK is split across packages rather than shipped as one bundle: @microsoft/rayfin-client is the main client SDK, with @microsoft/rayfin-data, @microsoft/rayfin-auth and @microsoft/rayfin-storage covering Data API Builder endpoints, authentication and storage operations.

### How do I deploy a Rayfin app to Microsoft Fabric?

The README shows npx rayfin up as the deploy-and-run command after scaffolding with npm create @microsoft/rayfin@latest. The README does not document the prompts or target selection, so read the console output on the first run.

## Sources

- [Issues](https://github.com/microsoft/rayfin/issues)
- [License: MIT](https://github.com/microsoft/rayfin/blob/main/LICENSE)
- [microsoft/rayfin on GitHub](https://github.com/microsoft/rayfin)
- [README](https://github.com/microsoft/rayfin/blob/main/README.md)
- [Releases](https://github.com/microsoft/rayfin/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/microsoft-rayfin
